CVE-2022-46161

CRITICAL

pdfmake <= 0.2.5 - Remote Code Execution via Unsafe Evaluation

Title source: llm
STIX 2.1

Description

pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evaluation of user controlled input. Users of pdfmake are thus subject to arbitrary code execution in the context of the process running the pdfmake code. There are no known fixes for this issue. Users are advised to restrict access to trusted user input.

References (2)

Core 2

Scores

CVSS v3 10.0
EPSS 0.0158
EPSS Percentile 72.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
pdfmake/pdfmake < 0.2.5
Published Dec 06, 2022
Tracked Since Feb 18, 2026